|
|
Log in / Subscribe / Register

Talking to McHardy & misplaced blame for his actions

Talking to McHardy & misplaced blame for his actions

Posted Aug 25, 2017 16:42 UTC (Fri) by bkuhn (subscriber, #58642)
In reply to: One-sided reporting by zdzichu
Parent article: Patrick McHardy and copyright profiteering (Opensource.com)

[McHardy] is a real person, member of our community. Can we have a proper interview with him?

As you can see on Conservancy's site, we were the first people, in coordination with the Netfilter team who did so simultaneously, to publicly criticize McHardy's behavior. We didn't take that action lightly. I talked with McHardy on the phone on almost exactly three years ago, on 29 August 2014. At the time, he expressed interest in joining Conservancy's coalition of Linux copyright holders who enforce GPL together, and it seemed to me at the time that his intention was to engage in the type of enforcement that is designed to increase the freedom of users by ensuring they get source code.

I sent email follow-ups to Patrick after that phone call throughout the rest of 2014 and regularly through 2015. I had his mobile number so I also texted him many times with no reply. Throughout early 2015, it became clear that his lawsuits were not in the spirit of community-oriented GPL enforcement. He sent just one reply, in April 2015, where he accused me of contacting him on behalf of one of the violators he sued (which of course wasn't true), and made many strange arguments about why he was justified in demanding large sums of money. I wrote back to continue the discussion, including many emails and text messages over many months following that, and he again went silent.

Conservancy launched the drafting Principles of Community-Oriented GPL enforcement in part because it became clear during mid-2015 that Patrick McHardy's enforcement didn't follow the unwritten principles that Conservancy's, the FSF's, and Harald Welte's enforcement had always followed. We were able to gain consensus and/or endorsement from most organizations in Open Source and Free Software (including the Netfilter Team) for the Principles, but sadly Patrick still doesn't answer my emails or text messages. I last tried to contact him in July 2016. I eventually just gave up, but I welcome him to contact me at any time to talk through what's happened and how to fix it.

Speaking for my experience, the most difficult part of what McHardy is doing is as follows: Conservancy (perhaps because we are willing to engage in public dialogue when Patrick is not) , has had to bear constant attacks from organizations like the Linux Foundation who are legitimately upset about the McHardy enforcement, but misplace their anger toward Conservancy. (This includes public name-calling and personal attacks on me and Karen Sandler by Linux Foundation employees.) The powerful forces who are nervous about GPL enforcement actually seem to blame us for McHardy's behavior. While it's a bizarre position on their part, it is at least understandable: Linux Foundation folks really seem to believe that GPL enforcement will “kill Linux”. As I pointed out in my FOSDEM 2017 keynote, if Linux was going to be killed specifically by GPL enforcement, Harald's enforcement in the early 2000s would have been what did it.


to post comments

Talking to McHardy & misplaced blame for his actions

Posted Aug 25, 2017 20:06 UTC (Fri) by linuxrocks123 (subscriber, #34648) [Link] (16 responses)

It would be an extreme action, but ... how big a contributor to Linux is/was Patrick? Would it be practical to just rip out and reimplement his code, to get rid of his legal ability to do this?

Talking to McHardy & misplaced blame for his actions

Posted Aug 25, 2017 21:31 UTC (Fri) by ms-tg (subscriber, #89231) [Link] (15 responses)

I was also wondering this?

Talking to McHardy & misplaced blame for his actions

Posted Aug 25, 2017 21:32 UTC (Fri) by pboddie (guest, #50784) [Link] (14 responses)

You'd think that if the Linux Foundation were so upset about it, they'd even pay for it.

Talking to McHardy & misplaced blame for his actions

Posted Aug 25, 2017 22:04 UTC (Fri) by corbet (editor, #1) [Link] (13 responses)

I have been in various settings where such ideas have been discussed. Ripping and replacing is definitely on people's radar. I don't know of any effort to actually do it at this point, though.

Removing code doesn't really solve the problem

Posted Aug 25, 2017 22:48 UTC (Fri) by bkuhn (subscriber, #58642) [Link] (12 responses)

corbet's right that people have talked about replacing code a lot, and not just regarding McHardy. Some have even proposed there should be a "litmus test" about enforcement views before accepting any contribution to Linux and refusing to permit code in canonical versions unless each contributor agrees not to enforce. It's a scary prospect to think about some sort of purity test on enforcement before merging contributions. That's just a form of CLA, so I do hope such a proposal will be DOA, but in the current political climate, that proposal is gaining fans in the for-profit companies that use Linux.

But, removing code is actually not as useful as it looks, particularly given the business model that McHardy is chasing. The main strategy that McHardy appears to be using is to focus on companies who are small system integrators who don't do their own engineering of the actual operating system in their products. I've done plenty of GPL enforcement in that kind of situation, and these companies are usually just confused and need education to get into compliance (usually by picking a reputable, instead of a fly-by-night, upstream vendor). Conservancy does that education work in those scenarios, and helps the violator comply.

McHardy, by contrast, just asks for a cash settlement plus an agreement to pay more money if they can't figure out how to come into compliance in a few months on their own. Then, he cashes in on that clause when the confused company, having received no education, can't get into compliance in the time allotted. (I've been leaked a few of McHardy's settlement agreements, and they've been structured as I describe.)

So, how does this relate to writing his code out of Linux? Well, most of these types of companies use very old versions of Linux. I still see Linux 2.6 active, in the wild, in products, on the shelves today. Yes, they're low-end products from companies we've all never heard of (or that we all avoid because they are known to have sub-par products). But there are hundreds, perhaps thousands, of these kinds of embedded Linux manufacturers. It'll be at least a decade before they're all using versions of Linux being released today, so writing people's copyrights out with the goal of preventing GPL enforcement is just not very effective. (And with a ten year lag, it's not even a long-term solution. After all, no one had any thought that Patrick would decide to do this when he started contributing.)

The obvious solution to me is that we need lots of no-cost, freely licensed educational materials out there to help people understand how to comply with copyleft. That's why I work on The Copyleft Guide, and I have an open door policy that anyone who asks me about compliance questions, I try my best to answer them and/or improve the Guide to answer their questions. I wish more people would help me with this, but a lot of people with the expertise to help in this way have built a business around it, so they charge huge fees for training courses and/or consulting. That's why we see so many compliance tutorial products that are non-Free (in both senses of the word).

Removing code doesn't really solve the problem

Posted Aug 26, 2017 0:57 UTC (Sat) by perlwolf (guest, #46060) [Link] (1 responses)

While the ten year gap is a serious problem, writing McHardy out of the kernel would still be a useful step. It would be useful in court (with a well-researched lawyer) to limit damages by showing that the code that gives him standing is extremely low value (in fact, part of writing that code out of the kernel could be to document how little effort was required to remove it), and that the owners of the vast majority of the code have diagnosed McHardy as a far more serious issue that the defendants. "Defendant is found guilty, damages are determined to be one Euro, no award of legal costs!" would be wonderful verdict and a strong disincentive to McHardy to continue.

Removing code doesn't really solve the problem

Posted Aug 26, 2017 1:22 UTC (Sat) by bkuhn (subscriber, #58642) [Link]

The additional issue is that some execs and lawyers are overreacting to McHardy. Raising awareness about his inappropriate activities have already slowed him down. At this point, multiple people are out there ready to help anyone who is approached by McHardy to come into compliance. Conservancy, for example, would be glad to help anyone who comes to us and wants to comply with GPL.

What I've observed is the McHardy fear being blown out of proportion to disparage all GPL enforcement in general. There is no need to marshal extensive resources for the minor problem McHardy creates. That's why I support instead marshaling resources for freely available Copyleft compliance education materials, which will help not only the McHardy situation, but generally help everyone improve compliance so anyone who imitates McHardy will fail at the start. And, people who want to do enforcement the right way can and should do so; we published the Principles to guide such enforcement. More enforcement done properly will drown out the rare outlier.

Removing code doesn't really solve the problem

Posted Aug 28, 2017 9:21 UTC (Mon) by bangert (subscriber, #28342) [Link] (9 responses)

corbet's right that people have talked about replacing code a lot, and not just regarding McHardy. Some have even proposed there should be a "litmus test" about enforcement views before accepting any contribution to Linux and refusing to permit code in canonical versions unless each contributor agrees not to enforce. It's a scary prospect to think about some sort of purity test on enforcement before merging contributions. That's just a form of CLA, so I do hope such a proposal will be DOA, but in the current political climate, that proposal is gaining fans in the for-profit companies that use Linux.
or you could require all small and/or new contributions to be more permissive than GPL. the possibility to include GPL licensed stuff into the kernel is only awarded after a substantial contribution - say 1000 patches and at least 10000 lines changed.

Removing code doesn't really solve the problem

Posted Aug 28, 2017 13:23 UTC (Mon) by bkuhn (subscriber, #58642) [Link]

> you could require all small and/or new contributions to be more permissive than GPL. the
> possibility to include GPL licensed stuff into the kernel is only awarded after a substantial
> contribution

There are people who are proposing not permitting upstream code to be GPL'd, and some companies refuse to contribute under GPL, but I think refusing contributions of any size that aren't GPL'd is effectively disenfranchising contributors from their rights to chose the license of their contributions, as historically Linux contributors have been permitted to pick any GPLv2-compatible license.

Also, your system has logistical problems. If one contributor 10000 line changes, but at one line at a time, they would be required under your plan to contribute under non-copyleft virtually forever.

Removing code doesn't really solve the problem

Posted Aug 28, 2017 19:34 UTC (Mon) by mjg59 (subscriber, #23239) [Link] (7 responses)

> or you could require all small and/or new contributions to be more permissive than GPL.

If something's a derivative work of the kernel (which most code contributed to the kernel is), releasing it under a more permissive license isn't an option.

Removing code doesn't really solve the problem

Posted Aug 29, 2017 6:00 UTC (Tue) by Wol (subscriber, #4433) [Link] (6 responses)

But releasing your changes *is* (not that I agree with that - the kernel is GPL2, and to insist that contributors can't use that same licence on their changes seems incredibly unFree to me).

At the end of the day, the licence the contributor wishes to use MUST be the contributor's choice, if it's to have any real meaning. If I contribute to a project, I accept that I'm expected to use the same licence, and to tell me I can't is weird. If I wish to use a compatible licence, that should be MY choice, not someone else's (that's why I think this move to force a large number of kernel interfaces "gpl only" is wrong - if the *author* and copyright owner has no desire or intention of enforcing gpl on their code, it devalues the gpl to force them to use it!).

Oh the joys of arguing about copyright and licencing ... :-(

Cheers,
Wol

Removing code doesn't really solve the problem

Posted Aug 29, 2017 21:23 UTC (Tue) by bangert (subscriber, #28342) [Link] (5 responses)

a single player could probably not pull this off, but if a group of big users/contributors of linux (ie. google, facebook, red hat et. al) collectively said, they will not accept changes to the linux kernel which are not more permissive than GPLv2 (say MIT, BSD 2 clause or Apache) this could effectively lead to a fork of the kernel.

Removing code doesn't really solve the problem

Posted Aug 29, 2017 21:54 UTC (Tue) by mjg59 (subscriber, #23239) [Link] (4 responses)

Producing a patch that's derived from Linux but released under a more liberal license would be a violation of the GPL, so this isn't a meaningful option.

Removing code doesn't really solve the problem

Posted Aug 29, 2017 22:27 UTC (Tue) by Cyberax (✭ supporter ✭, #52523) [Link] (3 responses)

GPL requires for the whole derived work to be distributed under the terms no more restrictive than GPL.

But it's perfectly fine to have patch _themselves_ to be under BSD/MIT. They'll be useless without the GPL-ed code, of course.

Removing code doesn't really solve the problem

Posted Aug 29, 2017 22:36 UTC (Tue) by mjg59 (subscriber, #23239) [Link]

> GPL requires for the whole derived work to be distributed under the terms no more restrictive than GPL.

No, specifically under the terms of the GPL - you can't be more restrictive *or* more liberal.

> But it's perfectly fine to have patch _themselves_ to be under BSD/MIT.

I think that's only the case if there's an argument that the patch itself isn't a derived work of the kernel.

Removing code doesn't really solve the problem

Posted Aug 29, 2017 22:54 UTC (Tue) by ewan (guest, #5533) [Link] (1 responses)

The licence requires derived works to be GPLed - you're assuming that only the combination of patch + kernel is a derived work, and that the patch is not. Matthew's point is that it's virtually impossible to generate a patch that is not itself already a derived work of the kernel, so that's not the case.

This is akin to the arguments around the nVidia binary, and the ZFS and OpenAFS filesystems - they've all been able to show core code that had a pre-Linux history, and so was demonstrably not a derivative of Linux, but while that might be possible for leaf drivers, it's going to be rather harder to generate any patch to (say) the scheduler, or memory management or indeed the networking core code, that's not based on the current state of that code.

Removing code doesn't really solve the problem

Posted Sep 10, 2017 8:19 UTC (Sun) by Garak (guest, #99377) [Link]

The licence requires derived works to be GPLed - you're assuming that only the combination of patch + kernel is a derived work, and that the patch is not. Matthew's point is that it's virtually impossible to generate a patch that is not itself already a derived work of the kernel, so that's not the case.
I'm skeptical of that. I wonder if I wanted to try and sell 'patches' to Stephen King novels whether or not I could find a way to do it legally where Stephen King would have no legal ability from his copyright to stop me. Suppose in my contextless patches I had a convention of reversing, pig-latinizing or rot13ing character and place names and whatever else. I kind of feel like I could or should be able to legally do that regardless of what King would prefer. Obviously King doesn't have exclusive copyright over the word 'the', though perhaps for character names. The point I'd highlight is that for any customer to be able to read the modified story, would require that they first do business with King on his terms, then choose to do so with me, and then apply the patch themselves. In such a situation I struggle to see the ethical or legal harm I would be doing to anyone.

Talking to McHardy & misplaced blame for his actions

Posted Aug 29, 2017 4:53 UTC (Tue) by paulj (subscriber, #341) [Link] (8 responses)

Bradley,

There is a sustained campaign by large tech corporate industry to undermine copyleft. You are well aware of it, as you have been campaigning on this. As you say, the reaction to McHardy is almost /engineered/ by those corporate interests to further that campaign.

It's worth pausing and asking whether reacting to McHardy in a way to placate those interests is worthwhile. Will that help copyleft? Or will it help further legitimise that campaign? Does putting measures in place to stop McHardy(-like)? agreements (and he hasn't sued anyone has he, he has just reached private settlements, right?) do anything that will make those anti-copyleft corporates stop their campaign? I don't think it will personally.

There's a large segment of the tech industry that wants to get rid of the GPL, and wants permissive licensing, so that they'll be able to make proprietary products out of open-source. A lot of executives in the valley really dislike copyleft, cause they can't make money from it by taking the code, closing it off and selling it directly, as they'd like. Also, they have to spend money on educating engineers about open-source. They have to audit their software. What a drag!

Sacrificing McHardy to them will not change them, in my opinion. They'll take strength from it. Be careful not to undermine copyleft in doing so.

Talking to McHardy & misplaced blame for his actions

Posted Aug 29, 2017 5:52 UTC (Tue) by Wol (subscriber, #4433) [Link] (6 responses)

> Sacrificing McHardy to them will not change them, in my opinion. They'll take strength from it. Be careful not to undermine copyleft in doing so.

That's a risk you take. Shooting fifth-columnists risks making them martyrs. Not shooting them leaves poison in your midst. Damned if you do and damned if you don't. I'm not particularly principled in principle, I just think standing by your principles, in practice, pays off.

Throw McHardy to the wolves and take the consequences. At the end of the day, he clearly is profiteering (or do I mean privateering, same thing ...) off of Free Software and damaging "The Cause". He clearly is not part of "us", and does not *want* to be part of "us". So let's return the compliment ...

Cheers,
Wol

Talking to McHardy & misplaced blame for his actions

Posted Aug 29, 2017 6:30 UTC (Tue) by paulj (subscriber, #341) [Link] (5 responses)

What is "The Cause" exactly?

The guy wrote code that's widely used in Linux across the world. Clearly non-trivial, given how long it has lasted despite corporate disquiet with his enforcement activities. People are distributing that code in egregious breach of the licence, so clearly *utterly unlicensed* - a copyright violation.

He apparently (from what Bradley has written) has given re-sellers and integrators a chance to come into compliance, and obtained agreements from them to do so. Those re-sellers and integrators have then apparently ignored the issue, and continued to sell products in a manner outwith the licence. Though, the exact details are hard to come by.

The world is a complex place. It shouldn't be McHardy's place to have to further educate repeat copyright violators. Indeed, as the injured party, he _should not_ offer advice to the parties he has a complaint against (your lawyer will never let you do this, in a similar situation).

Talking to McHardy & misplaced blame for his actions

Posted Aug 29, 2017 13:31 UTC (Tue) by Wol (subscriber, #4433) [Link] (4 responses)

> What is "The Cause" exactly?

In quotes because I was - deliberately - being vague. I guess it's probably World Domination ... :-)

> The guy wrote code that's widely used in Linux across the world. Clearly non-trivial, given how long it has lasted despite corporate disquiet with his enforcement activities.

Complete non-sequitur. Have you ever worked on a software project? Have you any idea how much old and obsolete code there is lying around? EVEN IN THE LINUX KERNEL?!

If no-one is either (a) paid, or (b) has a serious itch to scratch, they're not going to do the work. And if McHardy's code is trivial - as it apparently is - then neither (a) or (b) is likely to happen.

> People are distributing that code in egregious breach of the licence, so clearly *utterly unlicensed* - a copyright violation.

And what do you mean by egregious? If they bought a complete product from someone else and are merely reselling it (which appears on several occasions to have been the case) then in those circumstances people do NOT expect to get bitten by Intellectual Property issues!

> He apparently (from what Bradley has written) has given re-sellers and integrators a chance to come into compliance, and obtained agreements from them to do so. Those re-sellers and integrators have then apparently ignored the issue, and continued to sell products in a manner outwith the licence. Though, the exact details are hard to come by.

That's the whole point. Details are hard to come by. Although it appears pretty clear that McHardy's settlements are intended to make subsequent compliance "tricky", shall we say. There's a legal name for that - "entrapment".

> The world is a complex place. It shouldn't be McHardy's place to have to further educate repeat copyright violators. Indeed, as the injured party, he _should not_ offer advice to the parties he has a complaint against (your lawyer will never let you do this, in a similar situation).

So your lawyer will actively frustrate your attempts to get your preferred resolution to the case? The job of a lawyer is to DO AS THEY'RE TOLD, and to GET THE BEST RESOLUTION POSSIBLE.

If, *in the client's eyes*, the best resolution is to get compliance with the licence, then it is the lawyer's DUTY to seek to achieve that, and if that means giving advice to the other party, then so be it.

Cheers,
Wol

Talking to McHardy & misplaced blame for his actions

Posted Aug 29, 2017 14:12 UTC (Tue) by anselm (subscriber, #2796) [Link] (2 responses)

From what we've been told, McHardy's game is to find someone who violates the GPL on “his” copyrighted code in the Linux kernel, say, for product A, and get them to agree to stop doing that. He gets to recover “attorney's fees” for that (a couple of thousand Euros or so) and part of the agreement is that further GPL violations on their part will attract an automatic much larger fine. He then goes away and comes back a few months later to see whether there are more violations, e.g., in product B. In that case the contractual fine kicks in.

If you're the company that is shaken down, paying a few thousand Euros to make the guy go away for the time being may not look that bad at first. The correct approach, however, is to say “thank you”, fix the GPL violation, and let the guy sue you in court for actual damages, which he may either not bother with in the end or else lose (it may be a more lucrative and less risky use of his time to go shake down somebody else instead). Whatever you do, you certainly do not want to commit to the future-automatic-penalty agreement.

Talking to McHardy & misplaced blame for his actions

Posted Aug 29, 2017 20:49 UTC (Tue) by paulj (subscriber, #341) [Link] (1 responses)

"his" - why the quotes? Is there any doubt about him having copyright in code in the kernel?

Also, is it possible the reason no one has contested his demands so far potentially because they havn't a leg to stand on?

Talking to McHardy & misplaced blame for his actions

Posted Aug 29, 2017 22:39 UTC (Tue) by anselm (subscriber, #2796) [Link]

Whether “they haven't a leg to stand on” would be up in the air. Remember that Christoph Hellwig got his case against VMware dismissed because the court thought his individual contributions to the Linux kernel weren't sufficient to give him standing to sue. If that happened to McHardy he would have a real problem right there, so this may be a strong disincentive for him to actually sue somebody (and, in effect, roll the dice about the ongoing viability of his “business model”).

The other problem is that German civil law only deals in actual damages, not punitive damages, so McHardy would have to prove in court to what extent he was personally defrauded by company XYZ's GPL violations, which again might be difficult to do in actual practice.

Finally, the future-contractual-penalty-for-copyright-and-trademark-violations racket here in Germany is the hallmark of sleazy lawyers. People who have been around the home computer scene in the 1980s and 1990s may remember the late Günter Freiherr von Gravenreuth, who basically turned this into a cottage industry, but the practice has been alive and kicking in various guises ever since.

Talking to McHardy & misplaced blame for his actions

Posted Aug 29, 2017 20:47 UTC (Tue) by paulj (subscriber, #341) [Link]

Old code can still be valuable code.

As for egregious, perhaps in the first instance it was not the reseller. However, his copyright was still being infringed upon egregiously by someone, somewhere upstream of the reseller. If I understand Bradley correctly, at that point McHardy does *not* get any significant money from them, and the reseller /is/ told about their GPL obligations, and they do sign up to becoming compliant.

The second instance, the reseller clearly can not claim to be unaware. That's the entire reason McHardy can at that point get more significant damages. I find it hard, on the face of those facts, to have much sympathy for these resellers - it seems to me they *chose* to keep infringing.

We've heard a lot about McHardy and his actions, though still very filtered paraphrasings (it would be really good if Bradley and/or others could make the copies of the agreements public, mod redactions of clearly identifying details).

We've heard very little detail though about these repeat GPL violators, who are supposedly so innocent. I'm a little sceptical on that.

Talking to McHardy & misplaced blame for his actions

Posted Aug 29, 2017 15:53 UTC (Tue) by bkuhn (subscriber, #58642) [Link]

McHardy is a guy making a mistake. There's no reason not to point it out. What I'm seeking to do is point out this mistake is not such a big deal. Perhaps I'm bad at politics because I refuse to lie about things, but I'm not going to lie and say what McHardy is doing is a good thing. It's not; it's a bad thing that's relatively minor as bad things go. Our political opponents, by contrast, are telling us the sky is falling because McHardy has made some small mistakes.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds